CVE-2015-9543

An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.

Published: 2020-02-19 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2015-9543 is rated Low Risk (24.8/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.41%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2015-9543

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.08% 0.41% +0.32%
2 2026-02-18 0.16% 0.08% -0.07%
3 2026-02-14 0.16%

Full EPSS history (6 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2015-9543

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
3.3 3.1 LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:L)
Some sensitive info could get out, but not a total data dump.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
1.8 1.4 [email protected]
2.1 2.0 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
3.9 2.9 [email protected]

Weakness enumeration for CVE-2015-9543

GitHub Security Advisory for CVE-2015-9543

GHSA-22jm-4hxw-35jf · Severity: low · Ecosystem: pip — OpenStack Nova can leak consoleauth token into log files

OS Trackers for CVE-2015-9543

vendor priority summary link
debian not yet assigned CVE-2015-9543 not yet assigned priority: Debian including 1 source packages (nova), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2015-9543
redhat low https://access.redhat.com/security/cve/CVE-2015-9543
suse medium CVE-2015-9543 severity moderate: SUSE including 13 source package names (openstack-nova, openstack-nova-api, …), 64 product×package rows across 6 product lines (HPE Helion OpenStack 8, HPE Helion OpenStack Cloud 8, … (6 product lines)): Known Not Affected 64. https://www.suse.com/security/cve/CVE-2015-9543/
ubuntu low CVE-2015-9543 low priority: Ubuntu including 1 source packages (nova), 11 status rows across 11 suites (bionic, eoan, focal, groovy, hirsute, impish, jammy, kinetic, trusty, upstream, xenial): released 9, DNE 1, ignored 1. https://ubuntu.com/security/CVE-2015-9543

Affected software / configurations for CVE-2015-9543

Vendor Product Version Raw CPE
openstack nova < 18.2.4 cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
openstack nova >= 19.0.0, < 19.1.0 cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
openstack nova >= 20.0.0, < 20.1.0 cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*

References for CVE-2015-9543

URL Tags
http://www.openwall.com/lists/oss-security/2020/02/19/2 Mailing List Patch Third Party Advisory
https://launchpad.net/bugs/1492140 Issue Tracking Third Party Advisory
https://review.opendev.org/220622 Third Party Advisory
https://security.openstack.org/ossa/OSSA-2020-001.html Patch Vendor Advisory
cvelogic Threat Intelligence